Security

How to push my new certs to all my UFs?

dionrivera
Path Finder

I'm using my on-prem DS to push out apps to my UFs. The current cert has expired, how can I push a new cert to my UFs? I see that in my DS, I have a directory /opt/splunk/etc/deployment-apps/100_splunkcloud/default/. In this directory I have a server.pem file with last year's date. Is this where I need to move the new pem file? I thought it was in the /opt/splunk/etc/deployment-apps/100_splunkcloud/local directory instead. 

 

Thank you!

Labels (1)
0 Karma

dionrivera
Path Finder

@chaker It's actually the cert that secures the connection to the DS.

0 Karma

chaker
Contributor

Ahh ok. For on premise, you will need to follow the docs for rewnewing the certificates. It could be as simple as 

"If you have previously configured certificates for your infrastructure, the process can be as simple as updating the expiring or expired certificate with the new certificate and restarting the Splunk platform instance to recognize the certificate."

https://docs.splunk.com/Documentation/Splunk/9.0.1/Security/RenewExistingCerts

Also worth noting that Splunk support will assist here if you have a valid support agreement.

0 Karma

chaker
Contributor

If I understand correctly, the certificate used to secure data feeds to Splunk Cloud has expired?

Have you tried downloading a new copy of the UF App from your Splunk Cloud environment and either deploying that or moving the valid certificate files into the exiting App?

The reason config is in default is because its the config provided by the App developer. An empty local directory impies you are using the defauts, and not overiding them with your own config.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...